Most companies buy their security twice.

Once in the subscription that is already running. Then again as antivirus, a password manager and an extra appliance. Those get bolted on — while the tools from the first invoice sit untouched in the admin console.

This is not a criticism. A licence does not announce what is inside it, and nobody reads a product matrix for pleasure.

It is still worth a look. Between where you are now and somewhere considerably better, there is usually no purchase — only a configuration.

Licensed is not switched on

Business Premium is the licence tier aimed at smaller companies. Compared with the standard packages it does not give you more Office. It gives you more control: rules for signing in, management of devices, stricter inspection of incoming mail.

What is active if nobody configures anything

Almost nothing. The components are present and sitting at factory defaults.

That is how two companies on an identical invoice end up in completely different positions. One has a licence. The other has a configuration.

Why you should not take this article's word for it

Which components sit in which licence is something Microsoft revises periodically. A blog post is the wrong source for that — including this one.

The right source is the licence overview in your own tenant. What is here is the list of levers to go looking for.

The way in is the login, not the network

The idea that a company has an inside and an outside comes from an era with a server room. It no longer holds.

Mailbox, files and accounting all hang off one login. Reachable from any network.

What that means for the firewall

This moves where security actually happens. A firewall at the premises never sees the connection from someone's kitchen table.

And a stolen password looks to it like an ordinary sign-in anyway. How that plays out in detail: the glossary entry on firewalls.

What conditional access does

Conditional access is the rule layer in front of the login. Instead of «correct password, come in» it tests conditions: who is signing in, from which device, from which country, for which application.

Three rules most companies can start with:

  • Second factor on every account, with no exception for the management team
  • Administrative functions reachable only from managed devices
  • Sign-ins from countries where nobody works get blocked rather than logged

The third sounds crude and is the most effective. It costs nobody anything, provided the travel exceptions are agreed in advance.

What the second factor achieves and where it stops: two-factor authentication.

The device as a condition

A rule like «managed devices only» presupposes that managed devices exist. That is what Intune is for.

It knows the devices and enforces a floor: encryption, current updates, a screen lock. And it removes company data remotely.

The case that proves it

A phone goes missing. Every company gets there eventually.

Without device management that is an evening on the telephone with an uncertain ending. With it, it is one click: the company data is gone and the family photos stay.

Where rollouts fail

On exactly that separation, when nobody explains it. «The company manages my phone» sounds like something other than what it is.

The pushback is then entirely reasonable — and it costs more time than the setup did.

Where the attempts actually land

The route into a company rarely runs through a technical hole. It runs through a message somebody believes.

The forged invoice. The request to redirect a payment. The sign-in page that looks like the real one. The patterns are set out under phishing.

What is not sharp by default in Exchange Online

A fair amount. More can be switched on: stricter inspection of attachments and links, warnings on external senders, rules against automatic forwarding to the outside.

The most inconspicuous rule

Forwarding. Anyone who takes over a mailbox sets up a silent forward first.

After that they read along — long after the password has been changed. Which is why that single rule saves more in a real incident than the antivirus does.

One identity, one switch

The more applications hang off the same login, the fewer places there are for an account to be forgotten.

That is the real benefit of single sign-on. Not the passwords you save, but the one switch when somebody leaves.

The flip side belongs with it: if everything hangs off one login, that one has to be protected properly. And you need a break-glass account that works independently of it.

«Zero trust» is not a product

The phrase appears on plenty of proposals and rarely means the same thing twice. Originally it describes a posture, not software.

No access is trusted merely because it comes from inside. Every request gets checked, every time.

The sections above are exactly that, minus the phrase. Check login, device and application separately and you have implemented zero trust — whether or not it appears on an invoice.

The converse holds too. A product with «zero trust» in its name does not replace that work. At best it supports it.

What Swiss law adds

The Federal Act on Data Protection does not prescribe a particular technology. It requires appropriate technical and organisational measures for processing personal data (Art. 8 FADP, SR 235.1).

What counts as appropriate follows from the risk and the state of the art.

Two points that routinely get missed

  • Delegating to a provider is permitted but does not remove your responsibility (Art. 9 FADP). Your contract with Microsoft is part of your documentation, not a substitute for it.
  • Data-security breaches posing a high risk must be reported to the FDPIC (Art. 24 FADP). Without a log of who reached what and when, you cannot say what left — and then you have to assume the worst case.

The reporting duty that probably does not apply to you

Since 1 April 2025 there has been a 24-hour reporting duty for cyberattacks, with sanctions in force since 1 October 2025.

It applies expressly to operators of critical infrastructure, not to SMEs in general. Conflate the two and you build a compliance programme that was never aimed at you.

Where the data sits

Microsoft has run datacentre regions in Switzerland since 2019. Microsoft 365 lets you pin the storage location of core data to them.

That is an argument to make to customers. It is not a statutory duty to keep data in the country.

If you are on Business Standard

Not every company has Business Premium. Standard covers Office, mailbox and files — but the control layer only in part.

What still works there

The second factor. It does not depend on the higher tier and is the single most effective measure there is. If you do nothing else, do that.

The same goes for separating administrative rights and the forwarding rule in Exchange. Both cost time and nothing else.

How you know the tier is not enough

Two questions. Do people work on personal devices with company data? And are there accounts that reach particularly sensitive data?

Two yeses mean the rules you need are not on offer in Standard. At that point moving tier is the cheaper answer than bolting a product alongside — and it pays back faster than the price list suggests.

The order we recommend

Not everything at once, and not in arbitrary sequence:

  1. Second factor for everyone, management and service accounts included
  2. Separate administrative rights — nobody works day to day in an account that can do everything
  3. Enrol devices, company hardware first, personal devices afterwards with separation
  4. Sharpen the Exchange rules, forwarding to the outside above all
  5. Tidy up permissions in the file store — see SharePoint
  6. Test the restore, not just the backup (backup)

Step 6 is the one most companies skip. A backup that has never been restored is an assumption.

What this does not solve

Configuration is no substitute for attention. A convincing forgery, sent to the right person at the right moment, gets through every rule — it breaks nothing technically, it persuades a human being.

Nor for ownership

Rules nobody reviews go stale. An exception opened «for a test» otherwise outlives every change of staff.

What that means in day-to-day operation: managed IT and IT security.

Where to read on

The gaps that exist regardless of Microsoft are set out in cyber security for SMEs.

Which parts of the licence lie idle beyond security: Microsoft 365 for SMEs.

How we handle setup and operation: Microsoft 365 and Modern Workplace.